Trojan Horses in Recruiting: A Red-Teaming Case Study on Indirect Prompt Injection in Standard vs. Reasoning Models
Fuente:
arXiv
Guardado en:
| Autor principal: | Wirth, Manuel |
|---|---|
| Formato: | Preprint |
| Publicado: |
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection Attacks
por: Syros, Georgios, et al.
Publicado: (2026)
por: Syros, Georgios, et al.
Publicado: (2026)
IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection
por: Chia-Pei, et al.
Publicado: (2026)
por: Chia-Pei, et al.
Publicado: (2026)
Whispers of Wealth: Red-Teaming Google's Agent Payments Protocol via Prompt Injection
por: Debi, Tanusree, et al.
Publicado: (2026)
por: Debi, Tanusree, et al.
Publicado: (2026)
AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
por: Wang, Zhun, et al.
Publicado: (2025)
por: Wang, Zhun, et al.
Publicado: (2025)
Defending against Indirect Prompt Injection by Instruction Detection
por: Wen, Tongyu, et al.
Publicado: (2025)
por: Wen, Tongyu, et al.
Publicado: (2025)
Red Teaming Large Reasoning Models
por: Chen, Jiawei, et al.
Publicado: (2025)
por: Chen, Jiawei, et al.
Publicado: (2025)
Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems
por: Chang, Hongyan, et al.
Publicado: (2026)
por: Chang, Hongyan, et al.
Publicado: (2026)
QueryIPI: Query-agnostic Indirect Prompt Injection on Coding Agents
por: Xie, Yuchong, et al.
Publicado: (2025)
por: Xie, Yuchong, et al.
Publicado: (2025)
LivePI: More Realistic Benchmarking of Agents Against Indirect Prompt Injection
por: Zhao, Lei, et al.
Publicado: (2026)
por: Zhao, Lei, et al.
Publicado: (2026)
ICON: Indirect Prompt Injection Defense for Agents based on Inference-Time Correction
por: Wang, Che, et al.
Publicado: (2026)
por: Wang, Che, et al.
Publicado: (2026)
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
por: Zhu, Kaijie, et al.
Publicado: (2025)
por: Zhu, Kaijie, et al.
Publicado: (2025)
Mind the Trojan Horse: Image Prompt Adapter Enabling Scalable and Deceptive Jailbreaking
por: Chen, Junxi, et al.
Publicado: (2025)
por: Chen, Junxi, et al.
Publicado: (2025)
AdapTools: Adaptive Tool-based Indirect Prompt Injection Attacks on Agentic LLMs
por: Wang, Che, et al.
Publicado: (2026)
por: Wang, Che, et al.
Publicado: (2026)
Trojan Activation Attack: Red-Teaming Large Language Models using Activation Steering for Safety-Alignment
por: Wang, Haoran, et al.
Publicado: (2023)
por: Wang, Haoran, et al.
Publicado: (2023)
Manipulating LLM Web Agents with Indirect Prompt Injection Attack via HTML Accessibility Tree
por: Johnson, Sam, et al.
Publicado: (2025)
por: Johnson, Sam, et al.
Publicado: (2025)
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
por: Zhao, Wei, et al.
Publicado: (2026)
por: Zhao, Wei, et al.
Publicado: (2026)
Architecting Secure AI Agents: Perspectives on System-Level Defenses Against Indirect Prompt Injection Attacks
por: Xiang, Chong, et al.
Publicado: (2026)
por: Xiang, Chong, et al.
Publicado: (2026)
How Vulnerable Are AI Agents to Indirect Prompt Injections? Insights from a Large-Scale Public Competition
por: Dziemian, Mateusz, et al.
Publicado: (2026)
por: Dziemian, Mateusz, et al.
Publicado: (2026)
The Cognitive Firewall:Securing Browser Based AI Agents Against Indirect Prompt Injection Via Hybrid Edge Cloud Defense
por: Lan, Qianlong, et al.
Publicado: (2026)
por: Lan, Qianlong, et al.
Publicado: (2026)
Red Teaming AI Red Teaming
por: Majumdar, Subhabrata, et al.
Publicado: (2025)
por: Majumdar, Subhabrata, et al.
Publicado: (2025)
Bypassing Prompt Injection Detectors through Evasive Injections
por: Rahman, Md Jahedur, et al.
Publicado: (2026)
por: Rahman, Md Jahedur, et al.
Publicado: (2026)
RedVisor: Reasoning-Aware Prompt Injection Defense via Zero-Copy KV Cache Reuse
por: Liu, Mingrui, et al.
Publicado: (2026)
por: Liu, Mingrui, et al.
Publicado: (2026)
PromptLocate: Localizing Prompt Injection Attacks
por: Jia, Yuqi, et al.
Publicado: (2025)
por: Jia, Yuqi, et al.
Publicado: (2025)
Defeating Prompt Injections by Design
por: Debenedetti, Edoardo, et al.
Publicado: (2025)
por: Debenedetti, Edoardo, et al.
Publicado: (2025)
Evaluation of Prompt Injection Defenses in Large Language Models
por: Deep, Priyal, et al.
Publicado: (2026)
por: Deep, Priyal, et al.
Publicado: (2026)
IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM Agents
por: An, Hengyu, et al.
Publicado: (2025)
por: An, Hengyu, et al.
Publicado: (2025)
When Reject Turns into Accept: Quantifying the Vulnerability of LLM-Based Scientific Reviewers to Indirect Prompt Injection
por: Sahoo, Devanshu, et al.
Publicado: (2025)
por: Sahoo, Devanshu, et al.
Publicado: (2025)
AutoRedTeamer: Autonomous Red Teaming with Lifelong Attack Integration
por: Zhou, Andy, et al.
Publicado: (2025)
por: Zhou, Andy, et al.
Publicado: (2025)
TrojanWhisper: Evaluating Pre-trained LLMs to Detect and Localize Hardware Trojans
por: Faruque, Md Omar, et al.
Publicado: (2024)
por: Faruque, Md Omar, et al.
Publicado: (2024)
TrojanDec: Data-free Detection of Trojan Inputs in Self-supervised Learning
por: Liu, Yupei, et al.
Publicado: (2025)
por: Liu, Yupei, et al.
Publicado: (2025)
PromptArmor: Simple yet Effective Prompt Injection Defenses
por: Shi, Tianneng, et al.
Publicado: (2025)
por: Shi, Tianneng, et al.
Publicado: (2025)
A Red Teaming Roadmap Towards System-Level Safety
por: Wang, Zifan, et al.
Publicado: (2025)
por: Wang, Zifan, et al.
Publicado: (2025)
Large Empirical Case Study: Go-Explore adapted for AI Red Team Testing
por: Bhatt, Manish, et al.
Publicado: (2025)
por: Bhatt, Manish, et al.
Publicado: (2025)
Token-Efficient Prompt Injection Attack: Provoking Cessation in LLM Reasoning via Adaptive Token Compression
por: Cui, Yu, et al.
Publicado: (2025)
por: Cui, Yu, et al.
Publicado: (2025)
Prompt Injection as an Emerging Threat: Evaluating the Resilience of Large Language Models
por: Ganiuly, Daniyal, et al.
Publicado: (2025)
por: Ganiuly, Daniyal, et al.
Publicado: (2025)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
por: Wang, Zhilong, et al.
Publicado: (2025)
por: Wang, Zhilong, et al.
Publicado: (2025)
Proteus: A Self-Evolving Red Team for Agent Skill Ecosystems
por: Zhou, Zhaojiacheng
Publicado: (2026)
por: Zhou, Zhaojiacheng
Publicado: (2026)
A Critical Evaluation of Defenses against Prompt Injection Attacks
por: Jia, Yuqi, et al.
Publicado: (2025)
por: Jia, Yuqi, et al.
Publicado: (2025)
CourtGuard: A Local, Multiagent Prompt Injection Classifier
por: Wu, Isaac, et al.
Publicado: (2025)
por: Wu, Isaac, et al.
Publicado: (2025)
When Search Goes Wrong: Red-Teaming Web-Augmented Large Language Models
por: Ou, Haoran, et al.
Publicado: (2025)
por: Ou, Haoran, et al.
Publicado: (2025)
Ejemplares similares
-
MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection Attacks
por: Syros, Georgios, et al.
Publicado: (2026) -
IPI-proxy: An Intercepting Proxy for Red-Teaming Web-Browsing AI Agents Against Indirect Prompt Injection
por: Chia-Pei, et al.
Publicado: (2026) -
Whispers of Wealth: Red-Teaming Google's Agent Payments Protocol via Prompt Injection
por: Debi, Tanusree, et al.
Publicado: (2026) -
AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents
por: Wang, Zhun, et al.
Publicado: (2025) -
Defending against Indirect Prompt Injection by Instruction Detection
por: Wen, Tongyu, et al.
Publicado: (2025)